{"record":{"id":"4f3363f1a535bf97","repo":"aio-libs/aiohttp","slug":"ssl-is-not-supported","errorCode":null,"errorMessage":"SSL is not supported.","messagePattern":"SSL is not supported\\.","errorType":"exception","errorClass":"RuntimeError","httpStatus":null,"severity":"error","filePath":"aiohttp/worker.py","lineNumber":223,"sourceCode":"        self.cfg.worker_int(self)\n\n        # wakeup closing process\n        self._notify_waiter_done()\n\n    def handle_abort(self, sig: int, frame: FrameType | None) -> None:\n        self.alive = False\n        self.exit_code = 1\n        self.cfg.worker_abort(self)\n        sys.exit(1)\n\n    @staticmethod\n    def _create_ssl_context(cfg: Any) -> \"SSLContext\":\n        \"\"\"Creates SSLContext instance for usage in asyncio.create_server.\n\n        See ssl.SSLSocket.__init__ for more details.\n        \"\"\"\n        if ssl is None:  # pragma: no cover\n            raise RuntimeError(\"SSL is not supported.\")\n\n        ctx = ssl.SSLContext(cfg.ssl_version)\n        ctx.load_cert_chain(cfg.certfile, cfg.keyfile)\n        ctx.verify_mode = cfg.cert_reqs\n        if cfg.ca_certs:\n            ctx.load_verify_locations(cfg.ca_certs)\n        if cfg.ciphers:\n            ctx.set_ciphers(cfg.ciphers)\n        return ctx\n\n    def _get_valid_log_format(self, source_format: str) -> str:\n        if source_format == self.DEFAULT_GUNICORN_LOG_FORMAT:\n            return self.DEFAULT_AIOHTTP_LOG_FORMAT\n        elif re.search(r\"%\\([^\\)]+\\)\", source_format):\n            raise ValueError(\n                \"Gunicorn's style options in form of `%(name)s` are not \"\n                \"supported for the log formatting. Please use aiohttp's \"\n                \"format specification to configure access log formatting: \"","sourceCodeStart":205,"sourceCodeEnd":241,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/worker.py#L205-L241","documentation":"Raised by GunicornWebWorker._create_ssl_context() when the ssl module is None, i.e. the running Python interpreter was compiled without OpenSSL support (`ssl` failed to import, caught at the top of worker.py). It is only reached when gunicorn is configured with SSL (cfg.is_ssl True) and the worker tries to build the SSLContext.","triggerScenarios":"Configuring gunicorn with --certfile/--ssl-ciphers (or a config that sets is_ssl) while running a Python build where `import ssl` fails. Common on minimal/self-compiled CPython without libssl dev headers, or some Alpine images missing openssl.","commonSituations":"Alpine/musl images without openssl installed; a custom-compiled Python without --with-openssl; a stripped/embedded Python distribution; CI base image that omits ca-certificates/openssl.","solutions":["Use a Python distribution built with SSL — the official python:3.x images, or install openssl/openssl-dev and ca-certificates on Alpine before building Python.","Verify in the same environment with `python -c \"import ssl; print(ssl.OPENSSL_VERSION)`.","If you did not intend TLS, remove the certfile/keyfile/ssl options from the gunicorn config so cfg.is_ssl is False.","Terminate TLS at a reverse proxy (nginx, a load balancer) and run the aiohttp worker without SSL."],"exampleFix":"// before (Alpine, no openssl)\nFROM python:3.12-alpine\nRUN pip install aiohttp\n# gunicorn --certfile server.crt ... -> raises\n\n// after\nFROM python:3.12-alpine\nRUN apk add --no-cache openssl ca-certificates\nRUN pip install aiohttp\n# or use the slim debian image which ships SSL:\nFROM python:3.12-slim","handlingStrategy":"validation","validationCode":"import ssl as _ssl\nif _ssl is None:\n    raise SystemExit('This Python has no ssl module; install OpenSSL or use a different image')","typeGuard":"def ssl_available() -> bool:\n    import sys\n    return sys.modules.get('ssl') is not None and sys.modules['ssl'] is not None","tryCatchPattern":"# surfaced as RuntimeError at worker boot; resolve in the environment, not in code.\n# Before launching gunicorn:\nimport ssl\nassert ssl.OPENSSL_VERSION","preventionTips":["Use a Python image built with OpenSSL (official python:3.x or python:3.x-slim).","On Alpine install openssl, libssl, and ca-certificates before building Python.","Terminate TLS at a reverse proxy if you cannot fix the interpreter's SSL support."],"tags":["gunicorn","ssl","deployment","environment","boot"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}